drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Zwei Probleme in libtomcrypt
Name: |
Zwei Probleme in libtomcrypt |
|
ID: |
FEDORA-2018-9d667bdff8 |
|
Distribution: |
Fedora |
|
Plattformen: |
Fedora 28 |
|
Datum: |
Do, 19. Juli 2018, 23:16 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12437
https://bugzilla.redhat.com/show_bug.cgi?id=1548709
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0739 |
|
Applikationen: |
LibTomCrypt |
|
Originalnachricht |
------------------------------------------------------------------------------- - Fedora Update Notification FEDORA-2018-9d667bdff8 2018-07-19 18:02:50.871311 ------------------------------------------------------------------------------- -
Name : libtomcrypt Product : Fedora 28 Version : 1.18.2 Release : 1.fc28 URL : http://www.libtom.net/ Summary : A comprehensive, portable cryptographic toolkit Description : A comprehensive, modular and portable cryptographic toolkit that provides developers with a vast array of well known published block ciphers, one-way hash functions, chaining modes, pseudo-random number generators, public key cryptography and a plethora of other routines.
Designed from the ground up to be very simple to use. It has a modular and standard API that allows new ciphers, hashes and PRNGs to be added or removed without change to the overall end application. It features easy to use functions and a complete user manual which has many source snippet examples.
------------------------------------------------------------------------------- - Update Information:
- Fix Side Channel Based ECDSA Key Extraction (CVE-2018-12437) (PR #408) - Fix potential stack overflow when DER flexi-decoding (CVE-2018-0739) (PR #373) - Fix two-key 3DES (PR #390) - Fix accelerated CTR mode (PR #359) - Fix Fortuna PRNG (PR #363) - Fix compilation on platforms where cc doesn't point to gcc (PR #382) - Fix using the wrong environment variable LT instead of LIBTOOL (PR #392) - Fix build on platforms where the compiler provides __WCHAR_MAX__ but wchar.h is not available (PR #390) - Fix & re-factor crypt_list_all_sizes() and crypt_list_all_constants() (PR #414) - Minor fixes (PR's #350 #351 #375 #377 #378 #379) ------------------------------------------------------------------------------- - ChangeLog:
* Sun Jul 8 2018 Simone Caronni <negativo17@gmail.com> - 1.18.2-1 - Udpate to 1.18.2. * Wed Apr 18 2018 Simone Caronni <negativo17@gmail.com> - 1.18.1-5 - Update build requirement for texlive rebase. * Mon Apr 9 2018 Rafael Santos <rdossant@redhat.com> - 1.18.1-4 - Fix missing Fedora linker flags (bug #1548709) ------------------------------------------------------------------------------- - References:
[ 1 ] Bug #1591906 - CVE-2018-12437 libtomcrypt: memory-cache side-channel attack on ECDSA signatures [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1591906 [ 2 ] Bug #1591905 - CVE-2018-12437 libtomcrypt: memory-cache side-channel attack on ECDSA signatures [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1591905 [ 3 ] Bug #1548709 - libtomcrypt: Partial build flags injection https://bugzilla.redhat.com/show_bug.cgi?id=1548709 ------------------------------------------------------------------------------- -
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-9d667bdff8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys ------------------------------------------------------------------------------- - _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QK736OE4RNCZIYFQDERCQPXBRYI4AXA6/
|
|
|
|